Re: Plans for Post-Quantum Cryptography in GnuPG

"Robert J. Hansen via Gnupg-users" <[email protected]> Sun, 12 Apr 2026 22:37:16 -0400
Newsgroups gmane.comp.encryption.gpg.user
Message-ID <[email protected]>
> I would like to know if there are any plans for GnuPG to support
> post-quantum cryptography schemes, specifically ML-KEM (Kyber) and
> ML-DSA (Dilithium) as these will be crucial in cryptography that is
> resistant to quantum computer attacks (a fast-growing threat).

Kyber is already present in the latest 2.5 series, which is (despite its 
developmental version number) a GA release intended for all users.

There is no support at present for PQC in signing/certifying algorithms, 
as the demand there seems slightly less. (And before anyone screams "how 
can it be less?!", this is less in terms of user demand, and your voice 
is in the minority.)

IMO, the necessary algorithms for PQC signing/certifying are not yet 
ready for primetime. Dilithium is obviously the biggest component of a 
signing/certifying system, but there are others, and things are still 
evolving on the cryptography front. I'm sure that once things stabilize 
LibrePGP will start supporting it quickly enough.

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQR9jsS4W2/t1sENPHkeepTU6H+R1QUCadxW3AUDAAAAAAAKCRAeepTU6H+R1Yve
AQDOmdps4aFALPhZ4QvC41QdHR5JTH6+RaMjdBLVpYgfIAD/eRVNd9AzdldHGsH/HFJTlgYfWwgd
CGmyRcqR6XpTQgk=
=IzkC
-----END PGP SIGNATURE-----